Website Technology & Tech Stack Detector: BuiltWith Alternative
Pricing
from $10.00 / 1,000 website analyseds
Website Technology & Tech Stack Detector: BuiltWith Alternative
Website technology detector and tech stack lookup for any list of sites, a Wappalyzer and BuiltWith alternative: CMS, shop system (Shopify, Shopware, WooCommerce), analytics, consent manager, CDN and frameworks, plus email provider and SaaS from DNS, and GDPR signals. Weekly change monitor.
Pricing
from $10.00 / 1,000 website analyseds
Rating
0.0
(0)
Developer
Lindenwerk Data
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
12 hours ago
Last modified
Categories
Share
What is Website Technology & Tech Stack Detector?
See what any website is built with (CMS, shop system, analytics, consent manager, CDN, frameworks, email provider), one row per site. USD 0.01 per analysed site (USD 10 per 1,000); blocked sites with DNS results USD 0.002; sites with nothing detected are free. No login, cookies, proxies or third-party API key: paste domains, get JSON, CSV or Excel back.
A bulk website technology lookup that shows what any website is built with: CMS, shop system, analytics, consent manager, CDN, JavaScript frameworks, payment providers, chat widgets and hosting. DNS records add the email provider (Google Workspace, Microsoft 365 ...), email-sending services and SaaS tools verified on the domain (Atlassian, HubSpot, Zoom, DocuSign ...). Optional GDPR/DSGVO signals cover consent manager, trackers that run before consent, Google Fonts and YouTube embeds, plus security headers.
Paste 10 or 10,000 domains and get a spreadsheet-ready table back. It's a lightweight alternative to Wappalyzer and BuiltWith for lead lists, competitor research, agency audits and AI agents.
Who it's for
- Agencies and freelancers selling web, Shopify, Shopware or TYPO3 services. Build lead lists such as "all shops on Shopware 5", "WordPress sites without a consent manager" or "sites still loading Google Fonts from Google".
- Sales and RevOps teams. Enrich account lists with technographics: shop system, marketing automation, CRM-verified domains and email provider (Microsoft 365 vs Google Workspace).
- SaaS founders and product marketers. See who uses your competitor's widget, and track switches week by week with the built-in change monitor.
- Privacy and compliance consultants (DSGVO). Run a quick first-pass check across many sites: consent manager present, trackers that are not consent-gated, Google Fonts, YouTube without nocookie, missing imprint or privacy link.
- AI agents and LLM workflows. Small, structured JSON per site, easy to call over the Apify MCP server (see Use it from AI agents (MCP)).
What it detects
About 370 technologies in 54 categories, chosen for what matters in Europe (DACH, FR, NL) as well as global tools:
| Area | Examples |
|---|---|
| CMS / website builders | WordPress, TYPO3, Drupal, Joomla, Contao, Neos, Ghost, Webflow, Wix, Squarespace, Jimdo, IONOS MyWebsite |
| Ecommerce | Shopify (incl. headless), Shopware 5/6, WooCommerce, Magento / Adobe Commerce, OXID, JTL-Shop, Gambio, PrestaShop, Plentymarkets, Salesforce Commerce Cloud |
| Consent management (CMP) | Usercentrics, Cookiebot, OneTrust, Borlabs Cookie, consentmanager.net, CCM19, Didomi, Sourcepoint, Klaro, Complianz |
| Analytics & ads | Google Analytics 4, Google Tag Manager, Matomo, etracker, Adobe Analytics, Plausible, Hotjar, Meta Pixel, LinkedIn Insight, TikTok Pixel, Criteo, AWIN |
| Frameworks | React, Next.js, Vue, Nuxt, Angular, Svelte, Astro, Gatsby, Hugo, jQuery, Bootstrap, Tailwind |
| Infrastructure | Cloudflare, Akamai, Fastly, CloudFront, Vercel, Netlify, nginx, Apache, IIS, LiteSpeed, Hetzner / IONOS / STRATO / AWS / Azure DNS |
| Email (DNS) | Google Workspace, Microsoft 365, IONOS, STRATO, Proton, Zoho; sending via SendGrid, Mailgun, Amazon SES, Mailchimp/Mandrill, Brevo, Mailjet; email security (Proofpoint, Mimecast, Retarus) |
| SaaS verified in DNS | Atlassian, HubSpot, Salesforce, Zoom, Webex, DocuSign, Miro, Adobe, Apple, Meta Business, OpenAI ... (record type only, never the token value) |
| Other | Payments (Stripe, PayPal, Klarna, Adyen, Mollie, Unzer), chat (Intercom, Zendesk, Userlike, HubSpot chat), recruiting links (Personio, softgarden, Greenhouse, Workday), reCAPTCHA / hCaptcha / Friendly Captcha, video, maps, fonts |
Every detection has a confidence score (0-100), the sources that found it (meta, header, cookie, script, url, html, dns, implied) and up to three short evidence snippets, so you can check why it was reported. Versions are filled in where the site exposes them (meta generator, script URLs, Server / X-Powered-By headers).
Why this Actor
- HTML + DNS in one row. Pure HTML detectors miss the email provider and back-office SaaS. Pure DNS tools miss the CMS. This Actor does both in one call.
- It still works on sites that block bots. Many large shops answer data-center requests with 403. Instead of an empty row you get a cheaper partial result: DNS facts plus headers (CDN, server), billed at a fifth of the price. Sites with nothing detected are free.
- GDPR/DSGVO signals built in. You can see which trackers are executable in the HTML before consent and which are
held back by the consent manager (
type="text/plain",data-cookieconsent,data-usercentrics...). That makes it practical for privacy audits and for prospecting agencies. - Change monitor. Set a
monitorKey, schedule weekly, and every row tells you which technologies were added or removed since the last run. Turn ononlyChangedto receive (and pay for) only the sites that changed. - Polite and lawful by design. It reads robots.txt first and honours it, makes one page request per site, sends
a clear user agent, never logs in, never solves captchas and uses no proxies. It reads cookie names only, never
values, and ignores
mailto:/tel:links. It collects no personal data (details below). - Fast and cheap. In our measurement, 60 real sites took about 58 s at 512 MB of memory.
How to look up the tech stack of a website
- Click Start with the three prefilled websites to see real output in a few seconds.
- Paste your own domains or URLs into Websites, one per line (10 or 10,000).
- Keep DNS analysis on for the email provider and SaaS tools; switch on GDPR signals or security headers if you need them.
- Look at the results in the Output tab (views such as "Overview", "By category" and "GDPR & security") or download them as JSON, CSV or Excel.
- To track changes, set a Monitor key, save the input as a task and add a weekly schedule: each row then lists technologies added or removed since the last run.
- Send results on with Apify integrations (Slack, Google Drive, Make, Zapier, n8n or a webhook), or call the Actor through the Apify API or from AI agents via MCP.
Input
Only urls is required.
{"urls": ["typo3.org", "shopware.com", "https://www.bergfreunde.de/", "example.com"],"includeDns": true,"includeGdprSignals": true,"includeSecurityHeaders": true,"includeEvidence": true}
Lead list: shop systems and consent managers only, with less output:
{"urls": ["shop-a.de", "shop-b.at", "shop-c.ch"],"categories": ["Ecommerce", "CMS", "Consent management", "Payments"],"includeEvidence": false,"minConfidence": 80}
Weekly competitor monitor. Schedule it in Apify Console:
{"urls": ["competitor-one.com", "competitor-two.de"],"monitorKey": "competitors","onlyChanged": true}
| Field | Default | What it does |
|---|---|---|
urls | none | Domains or URLs, one per line. Commas and spaces also work. Duplicates and www variants are merged. Aliases: startUrls, domains, websites, targetUrls, url, so inputs from other tech-stack Actors work unchanged. |
includeDns | true | MX, SPF, DMARC, NS, www CNAME, TXT verification records |
includeGdprSignals | true | Consent manager, ungated trackers, Google Fonts, YouTube/Maps embeds, imprint/privacy links, third-party hosts |
includeSecurityHeaders | true | HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HTTPS, score 0-7 |
includeEvidence | true | Up to three snippets per technology explaining the detection |
categories | all | Only return these categories |
minConfidence | 0 | Drop weaker detections |
monitorKey / onlyChanged | off | Change tracking between runs |
maxSites | 1000 | Safety limit (max 10,000 per run) |
maxConcurrency | 20 | Sites analysed in parallel |
requestTimeoutSecs | 15 | Per-request timeout |
Output
One row per website. This sample is shortened and taken from a real run:
{"domain": "typo3.org","finalUrl": "https://typo3.org/","httpStatus": 200,"fetchStatus": "ok","technologyCount": 8,"technologyNames": ["TYPO3", "Usercentrics", "Mailjet", "Google Workspace", "PHP", "Google Search Console","Google Tag Manager", "Apache HTTP Server"],"categories": {"CMS": "TYPO3", "Consent management": "Usercentrics", "Email provider": "Google Workspace"},"emailProviders": ["Google Workspace"],"technologies": [{"name": "TYPO3", "category": "CMS", "version": null, "confidence": 100, "sources": ["meta", "url", "html"],"evidence": ["meta generator=TYPO3 CMS", "html contains \"typo3temp/assets\""]}],"dns": {"mxHosts": ["smtp.google.com"], "spfPresent": true, "spfIncludes": ["spf.mailjet.com", "_spf.google.com"],"dmarcPolicy": "reject", "verificationTokens": ["google-site-verification="]},"gdpr": {"consentManagers": ["Usercentrics"], "trackersNotConsentGated": [], "googleFontsFromGoogle": false,"imprintLinkFound": true, "privacyPolicyLinkFound": true, "flags": []},"securityHeaders": {"strictTransportSecurity": true, "xFrameOptions": true, "contentSecurityPolicy": false, "score": 4, "scoreMax": 7},"changes": null,"chargedEvent": "site-analyzed"}
The dataset has ready-made views: Overview, By category, Technology details, GDPR & security,
DNS & email and Changes (monitor). You can export them as CSV, Excel, JSON or XML, or read them through the
API. RUN_SUMMARY in the key-value store holds counts per fetch status, billed rows, bytes downloaded and runtime.
fetchStatus values:
| Value | Meaning |
|---|---|
ok | Page analysed |
blocked | Bot protection (403/429/challenge). DNS and header detections are still returned. |
http_error | 4xx/5xx page |
not_html | The start URL is not a web page |
robots_disallowed | robots.txt does not allow our bot, so the page was not requested |
unreachable | The site could not be reached |
timeout | The request timed out |
refused_private_address | The host resolves to a private IP; refused for safety |
GDPR flags:
| Flag | Raised when |
|---|---|
GOOGLE_FONTS_LOADED_FROM_GOOGLE | Fonts are loaded from fonts.googleapis.com |
TRACKERS_BUT_NO_KNOWN_CONSENT_MANAGER | Trackers are present but no consent manager was found |
TRACKERS_NOT_CONSENT_GATED_IN_HTML | Trackers are executable in the HTML before consent |
YOUTUBE_EMBED_WITHOUT_NOCOOKIE | A YouTube embed does not use youtube-nocookie |
GOOGLE_MAPS_EMBEDDED | A Google Maps embed is on the page |
NO_IMPRINT_LINK_FOUND / NO_PRIVACY_POLICY_LINK_FOUND | The link was not found. Only checked when the page has at least 5 links; JavaScript-only pages report null. |
These are heuristic signals from the first HTML response, not legal advice.
Pricing (pay per event)
| Event | Price | When |
|---|---|---|
site-analyzed | USD 0.01 (USD 10 per 1,000 sites) | Page analysed and at least one technology found |
partial-result | USD 0.002 | Page blocked or unreachable, but DNS or headers still found technologies |
| Sites with no detection | free | For example, domains that don't exist or sites that are down |
| Actor start | USD 0.00005 | Apify platform minimum per run |
For comparison, BuiltWith's paid plans start at about USD 295 per month and Wappalyzer's API plans run to hundreds of dollars per month. Here, 1,000 sites cost at most USD 10 (plus USD 0.00005 per run) and there's no subscription. Set Maximum cost per run in Apify Console: the Actor stops cleanly when the limit is reached and never charges more.
Use it from AI agents (MCP)
AI agents and MCP clients (Claude, Cursor, VS Code, ChatGPT and others) can call this Actor as a tool through the
Apify MCP server at mcp.apify.com. To load only this Actor:
{"mcpServers": {"apify": {"url": "https://mcp.apify.com/?tools=lindenwerk/tech-stack-detector"}}}
The client signs in to Apify on first connection (OAuth). To use a token instead, add
"headers": {"Authorization": "Bearer <APIFY_TOKEN>"}. With the default server URL (https://mcp.apify.com) an agent
can also find the Actor with search-actors and run it with call-actor:
{"actor": "lindenwerk/tech-stack-detector","input": {"urls": ["typo3.org"],"includeDns": true,"includeGdprSignals": false,"includeSecurityHeaders": false,"includeEvidence": false,"maxSites": 1,"maxConcurrency": 1},"callOptions": {"memory": 256, "maxTotalChargeUsd": 0.02}}
This is examples/input-single-domain-agent.json: one domain, DNS on (email provider and SaaS), and GDPR signals,
security headers and evidence off for the shortest answer. call-actor returns the run status and dataset ID, and
the agent then reads the row with get-dataset-items. The row is compact JSON (real run on typo3.org, 2026-10-06;
the technologies list is shortened from 8 entries to 3):
{"input": "https://typo3.org/","domain": "typo3.org","url": "https://typo3.org/","finalUrl": "https://typo3.org/","httpStatus": 200,"fetchStatus": "ok","fetchNote": null,"pageTitle": "TYPO3 Project and Governance — Democratic Open Source - TYPO3 Project","language": "en-US","technologyCount": 8,"technologyNames": ["TYPO3", "Usercentrics", "Mailjet", "Google Workspace", "PHP", "Google Search Console","Google Tag Manager", "Apache HTTP Server"],"categories": {"CMS": "TYPO3", "Consent management": "Usercentrics", "Email marketing": "Mailjet","Email provider": "Google Workspace", "Programming language": "PHP", "SEO": "Google Search Console","Tag manager": "Google Tag Manager", "Web server": "Apache HTTP Server"},"emailProviders": ["Google Workspace"],"technologies": [{"name": "TYPO3", "category": "CMS", "version": null, "confidence": 100, "sources": ["meta", "url", "html"]},{"name": "Usercentrics", "category": "Consent management", "version": null, "confidence": 90, "sources": ["url", "html"]},{"name": "Google Workspace", "category": "Email provider", "version": null, "confidence": 95, "sources": ["dns"]}],"dns": {"domainExists": true, "mxHosts": ["smtp.google.com"], "spfPresent": true,"spfIncludes": ["spf.mailjet.com", "_spf.google.com", "mail.typo3.org"], "dmarcPolicy": "reject","verificationTokens": ["google-site-verification="]},"gdpr": null,"securityHeaders": null,"changes": null,"checkedAt": "2026-10-06T02:45:31+00:00","chargedEvent": "site-analyzed"}
What one call costs (pay per event; the Actor start is charged once per run up to 1 GB of memory):
| Outcome of the one domain | Events | Total |
|---|---|---|
| Page analysed, at least one technology | site-analyzed USD 0.01 + Actor start USD 0.00005 | USD 0.01005 |
| Page blocked or unreachable, DNS or headers still found something | partial-result USD 0.002 + start USD 0.00005 | USD 0.00205 |
| Nothing detected (for example a dead domain) | start only | USD 0.00005 |
The smallest run limit the Actor accepts is USD 0.02, which covers one site plus the start, so
maxTotalChargeUsd: 0.02 is enough for a single lookup. For many domains, send them in one call: 20 domains cost
20 × USD 0.01 + one start, not 20 starts.
Example prompts:
- "Which CMS, shop system and consent manager do these 20 prospects use?"
- "Does example.de use Google Workspace or Microsoft 365?"
- "Which of these sites load Google Fonts from Google or run trackers before consent?"
For short agent answers, keep includeEvidence: false and add a categories filter.
Without MCP, the same call over HTTP is
POST https://api.apify.com/v2/acts/lindenwerk~tech-stack-detector/run-sync-get-dataset-items?token=<APIFY_TOKEN>
with the input JSON as the body.
How it works and limits
- One robots.txt request and one GET of the start page per site, over https with an http fallback. It does not render JavaScript, so technologies that are injected only later by a tag manager can be missed. Server-rendered stacks (CMS, shops, CMPs, analytics tags) are detected reliably.
- DNS lookups use public resolvers. They report only the vendor or record type. Secret verification values are cut off, and DMARC report addresses are never output.
- Some large sites block all data-center traffic. Those rows come back as
blockedwith DNS and header results. - Detection is precision-first. Patterns are vendor hostnames, vendor-specific headers, cookie names and generator tags, not generic words, so a blog post that mentions "Shopify" is not reported as Shopify.
Data, privacy and responsible use
- No personal data. It reads technical metadata only: HTML markup, response headers, cookie names, and public DNS
records of the domain. It does not collect names, email addresses, phone numbers or account data. Contact links
(
mailto:,tel:) are skipped when the page is parsed. - Honours robots.txt (RFC 9309) for the user agent
LindenwerkTechStackBot. If robots.txt disallows the page, only DNS facts are returned. - It doesn't log in, bypass paywalls, solve captchas or circumvent bot protection.
- You are responsible for how you use the results, for example under GDPR or UWG when you contact businesses.
- The fingerprint database is original work by Lindenwerk Data. It is not a copy of Wappalyzer or BuiltWith data.
FAQ
How is it different from Wappalyzer or BuiltWith? It's an alternative to both for bulk lookups: pay per site, no subscription, no browser extension. It covers the same CMS, shop, analytics, CMP and framework layer, and adds DNS facts (email provider, SaaS verifications), GDPR signals and security headers in the same row. What it doesn't do: it has no historical database and no "find every site that uses X" search. It checks the domains you give it, and the change monitor builds your own history from the first run on. Lindenwerk Data is not affiliated with Wappalyzer or BuiltWith; the names only describe what this Actor is an alternative to, and its fingerprint database is original work.
How accurate is it? Detection is precision-first: vendor hostnames, vendor-specific headers, cookie names and
generator tags, each with a confidence score and evidence, so false positives are rare. The main limit is that it
reads the first HTML response and doesn't render JavaScript, so tools injected later by a tag manager can be missed.
Versions appear only where the site exposes them. For lead lists, minConfidence: 80 keeps only strong detections.
Why is a site "blocked"? Its bot protection refuses automated requests from cloud servers. We don't work around that on purpose. You still get DNS and header results for USD 0.002, and a site with nothing detected isn't charged.
Is it GDPR-compliant? It collects only public, non-personal technical data: HTML markup, response headers, cookie
names (never values) and public DNS records of the domain. It doesn't collect names, email addresses or phone
numbers, skips mailto: and tel: links, and never outputs DMARC report addresses or verification token values.
You remain responsible for how you use the results, for example when you contact businesses. The GDPR signals are
heuristics, not legal advice.
What does a single lookup cost? USD 0.01005 for an analysed site (USD 0.01 plus the USD 0.00005 start), USD 0.00205 for a blocked site with DNS results, and USD 0.00005 if nothing is detected. See Use it from AI agents (MCP).
Can I scan subpages? Yes. Pass full URLs, for example https://example.com/shop/. Each URL counts as one site.
How often should I monitor? Weekly is usually enough. Stacks change slowly.
Examples
- Detect the tech stack of competitor websites: a published example task with a ready-made input. Open it, adjust the input and run it in your own Apify account.
Other Lindenwerk Data Actors
- German & EU Tenders: Public Procurement Monitor: Ausschreibungen from oeffentlichevergabe.de and TED, deduplicated and scored to your CPV codes and keywords.
- France Tenders Monitor: BOAMP, TED & Marchés Publics: marchés publics from BOAMP and TED in one deduplicated, scored list.
- UK Tenders Monitor: Government Contracts & Find a Tender Alerts: Find a Tender notices (above and below threshold) as daily tender alerts, scored to your profile.
- SAM.gov Government Contract Opportunities Monitor: US federal bids and RFPs from SAM.gov, scored to your NAICS and set-asides.
- SEO Audit Crawler: Broken Links, llms.txt & AI Bot Check: on-page SEO, broken links, llms.txt and AI crawler check for whole websites.
- PDF to Markdown & RAG Chunks: Document Parser (DOCX/PPTX/XLSX): PDF, Word, PowerPoint and Excel to clean Markdown with inline tables and page-cited RAG chunks.
Deutsch (Kurzfassung)
Dieser Actor erkennt die Technik hinter beliebig vielen Websites: CMS (WordPress, TYPO3, Contao ...), Shopsystem (Shopware, Shopify, JTL, Gambio, OXID ...), Consent-Manager (Usercentrics, Cookiebot, Borlabs ...), Analytics, CDN und Frameworks. Über DNS kommen E-Mail-Anbieter (Microsoft 365, Google Workspace, IONOS, STRATO) und verifizierte SaaS-Tools dazu. Optional gibt es DSGVO-Signale: Tracker ohne Einwilligungs-Sperre, Google Fonts von Google-Servern, YouTube ohne nocookie, fehlender Impressum- oder Datenschutz-Link. Ideal für Agenturen (Leadlisten), Vertrieb (Technographics), Datenschutz-Erstchecks und Wettbewerbsbeobachtung mit wöchentlichem Änderungsmonitor. Preis: USD 0,01 pro analysierter Website, USD 0,002 für blockierte Websites mit DNS-Treffern; Websites ohne Treffer sind kostenlos. Kein Login und kein API-Schlüssel eines Drittanbieters nötig. Der Actor beachtet robots.txt, nutzt keine Proxys und erhebt keine personenbezogenen Daten. Die Signale sind Hinweise, keine Rechtsberatung.
Changelog
See the Changelog tab. Version 0.1 is the first public release.
Made by Lindenwerk Data.